Bug #103939
Updated by Patrick Schriner about 2 months ago
It should be possible to write a middleware that adds frontend CSPs without nonces being required.
Forcing nonce usage has a serious performance implication as in fact every request has to be partially uncached